सुरक्षा सलाह पर वापस जाएँ

Security: CVE-2026-93697 Stored XSS in WHM’s Account Modification Interfaces – September 29, 2026

CVE-2026-93697 is a stored XSS vulnerability in the WHM Mass Modify Accounts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can run script inside a WHM administrator's session, so update cPanel/WHM to a patched release promptly.

Critical 9 CVSS
cPanel

SharedLicense लाइसेंस के तहत इसका अर्थ

Successful exploitation lets an unprivileged account holder execute script in the context of a WHM administrator's session and perform administrative actions as that user.

Situation

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • 11.110.0.148 or later
  • 11.134.0.61 or later
  • 11.136.0.45 or later
  • 11.138.0.11 or later
  • WP2: 11.138.1.13 or later

Impact

Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-93697?
It is the CVE ID cPanel assigned to a stored XSS vulnerability in the WHM Mass Modify Accounts interface (one of the account modification interfaces), published September 29, 2026. All supported cPanel/WHM versions are affected. cPanel has not published a CVSS score for it yet.
Which cPanel/WHM versions are affected and which are patched?
All supported cPanel/WHM versions are affected. Patched versions are 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11 or later — the fix spans the 11.110, 11.134, 11.136 and 11.138 release tiers, plus WP2 11.138.1.13.
How do I fix CVE-2026-93697?
Update cPanel/WHM: run sudo /scripts/upcp --force. The fix landed in 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11 or later (WP2: 11.138.1.13 or later).
Is CVE-2026-93697 being exploited in the wild?
cPanel's advisory does not report any active exploitation, and no CVSS score has been published yet. Because the impact ranges from admin-session takeover to root code execution, treat the update as urgent.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें